Live data from Hacker News

Google Chrome Hacked?

vupen.com

1–10 of 223 posts

Re: Google Chrome Hacked?

#2
"This code and the technical details of the underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers"

Love the capital G.

Re: Google Chrome Hacked?

#3
> This code and the [...] underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers

And the vendor, I hope? Of course, we know HBGary was developing private exploits, but it wasn't exactly blogging about them.

Re: Google Chrome Hacked?

#4

> This code and the [...] underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers And the vendor, I hope? Of course, we know HBGary was developing private exploits, but it wasn't exactly blogging about them.

I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but with Google their window has the potential to be very short.

Re: Google Chrome Hacked?

#6
Their site seems to be going down, so here's the text:

---

Hi everyone,

We are (un)happy to announce that we have officially Pwnd Google Chrome and its sandbox.

The exploit shown in this video is one of the most sophisticated codes we have seen and created so far as it bypasses all security features including ASLR/DEP/Sandbox, it is silent (no crash after executing the payload), it relies on undisclosed (0day) vulnerabilities discovered by VUPEN and it works on all Windows systems (32-bit and x64).

The video shows the exploit in action with Google Chrome v11.0.696.65 on Microsoft Windows 7 SP1 (x64). The user is tricked into visiting a specially crafted web page hosting the exploit which will execute various payloads to ultimately download the Calculator from a remote location and launch it outside the sandbox at Medium integrity level. Note: The Calculator is used here as an example, it can be replaced by any other payload.

While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own contest during the last three years, we have now uncovered a reliable way to execute arbitrary code on any installation of Chrome despite its sandbox, ASLR and DEP.

This code and the technical details of the underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers as part of our vulnerability research services.

The video in question is http://www.youtube.com/watch?feature=player_embedded&v=c...

Re: Google Chrome Hacked?

#7
post #4

> This code and the [...] underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers And the vendor, I hope? Of course, we know HBGary was developing private exploits, but it wasn't exactly blogging about them.

I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but with Google their window has the potential to be very short.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

Re: Google Chrome Hacked?

#8
I can understand their joy but the last sentence in the post and the Twitter update: "Sorry Google...we have officially pwned Google Chrome and its sandbox with a 0-Day." [1] seem rather unprofessional for the "world leader in vulnerability research for defensive and offensive security" [2], a company with "Government customers".

[1] https://twitter.com/VUPEN

[2] http://www.vupen.com/english/company.php

Re: Google Chrome Hacked?

#9

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

like it or not, it's been vernacular for quite some time. how do you feel about pwn2own? the pwnies?

Re: Google Chrome Hacked?

#10
post #7
post #4

Earlier quoted context omitted.

I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but with Google their window has the potential to be very short.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

http://www.vupen.com/english/services/

> As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers.

Note also the "under contract with VUPEN" part of the disclosure bit.

Post reply on HN